Home > Information Security News > RIM patches serious BlackBerry Attachment Service flaws
Information Security News:
EMAIL THIS

RIM patches serious BlackBerry Attachment Service flaws

By SearchSecurity.com Staff
28 May 2009 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Research In Motion issued an update to the BlackBerry Enterprise Server correcting serious PDF handling flaws.

The vulnerabilities are contained in the BlackBerry Attachment Service component. Users are at risk if they open a malicious PDF file on their BlackBerry smartphone. In its advisory, RIM said the vulnerabilities could be used by an attacker to cause memory corruption leading to arbitrary code execution on the machine that hosts the BlackBerry Attachment Service.

The flaws could be found in BlackBerry Enterprise Server software version 4.1.3 through 5.0. and BlackBerry Professional Software 4.1.4. The vulnerabilities are potentially very serious. They carry a Common Vulnerability Scoring System (CVSS) score of 9.3, RIM said.

Security update 4 has been released. For BlackBerry Enterprise Server version 4.1x and 5.0 users. A separate security update has been released for affected BlackBerry Professional Software versions.

RIM has had ongoing security issues with its PDF distiller. The smartphone maker issued an update correcting flaws in the BlackBerry Attachment Service in April. Separate updates were released in January and in July 2008 to correct flaws.

Tags: Secure Coding and Application ProgrammingWeb Application SecurityDatabase Security Tools and TechniquesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Secure Coding and Application Programming
Improving software with the Building Security in Maturity Model (BSIMM)
SANS Institute, MITRE release new top 25 dangerous coding errors list
Code complexity analysis: How to keep it simple
Active PDF attacks target Reader, Acrobat zero-day vulnerability
Software piracy group offers cash to whistleblowers
SQL injection detection tools and prevention strategies
Cross-site scripting explained: How to prevent attacks
H.D. Moore speaks about Metasploit Project deal, Release 3.3
Metasploit Project acquired by vulnerability management firm Rapid7
Will Web application firewalls (WAFs) catch most security vulnerabilities?

Web Application Security
CISOs take measured steps to reduce social media risks
Google to pay for Chrome browser vulnerabilities
Facebook, McAfee partner to fix social network security issues
PDF attack code complicates security analysis, skirts detection
Annual security reports offer some hope
Firefox, Opera, Safari browsers top list of high risk software
Active PDF attacks target Reader, Acrobat zero-day vulnerability
Using unique device identification for bank website security
Avoid common Web application firewall configuration errors
Microsoft gives Internet Explorer a major security overhaul

Database Security Tools and Techniques
Multifunction security device safeguards SOA, streamlines company's infrastructure
Safend expands data leakage prevention product to plug more gaps
How to prevent memory dump attacks
Database activity monitoring lacks security lift
Report: Firms avoid encrypting backup tapes, databases
Cryptography for the rest of us
Recent breaches show data theft prevention basics lacking
Unpatched vulnerability discovered in Microsoft SQL Server
How to use Excel for security log data analysis
SQL injection continues to trouble firms, lead to breaches

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts